2026 CVE Vulnerabilities

43,277 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-59214CRITICAL9Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs c...
CVE-2026-58459CRITICAL9.6gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows ...
CVE-2026-51599CRITICAL9.8An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n al...
CVE-2026-51597CRITICAL9.1MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authenticat...
CVE-2026-13461CRITICAL9.6When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 ...
CVE-2026-42486CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-23562CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-23561CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-23560CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-23559CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-23556CRITICAL9.4When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ...
CVE-2026-14261CRITICAL9.1A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation ...
CVE-2026-12116CRITICAL9.8A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings,...
CVE-2026-56291CRITICAL9.8Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension B...
CVE-2026-5955CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software an...
CVE-2026-2342CRITICAL9.3Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Inform...
CVE-2026-15158CRITICAL9.8The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, ...
CVE-2026-14245CRITICAL9.8The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass...
CVE-2026-47840CRITICAL9.3A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate fro...
CVE-2026-47826CRITICAL9.1The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfi...
CVE-2026-54782CRITICAL10CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ...
CVE-2026-15113CRITICAL9.6Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially ...
CVE-2026-55471CRITICAL9.1HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10...
CVE-2026-52200CRITICAL9.8An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax...
CVE-2026-44024CRITICAL9.8Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now